CVE-2026-98362
In the Linux kernel, the following vulnerability has been resolved: clk: scpi: bound-check DVFS index in scpi_dvfs_recalc_rate dvfs_get_idx() may return an out-of-range index if the SCP firmware is buggy or returns a stale value. Only negative indexes were rejected, so a large index walked past info->opps and could treat garbage as a clock rate (KASAN OOB / wrong frequency to consumers). The missing upper bound dates back to the original SCPI clock driver. Treat indexes >= opp count as invalid and return 0, same as idx < 0.
Affected versions
Linux kernel versions
4.4
and later are affected. Fixed in
5.10.271,
5.15.222,
6.1.189,
6.6.158,
6.12.112,
6.18.54,
7.2.8,
7.3-rc4
and their respective stable series.
References
8 totalFrequently asked questions
-
What is CVE-2026-98362?
CVE-2026-98362 is a unscored severity Linux kernel vulnerability . It affects Linux kernel versions from 4.4 onward and has been patched in 5.10.271, 5.15.222, 6.1.189 and others. CVE-2026-98362 has not been confirmed as actively exploited and is not listed in the CISA KEV catalog.
-
Is there a patch available for CVE-2026-98362?
Yes. CVE-2026-98362 has been patched. Fixed versions include 5.10.271, 5.15.222, 6.1.189 and others. If you are running Linux kernel 4.4 or later up to the fix versions, apply the relevant patch for your kernel branch.
-
Is CVE-2026-98362 actively exploited?
No. CVE-2026-98362 has not been confirmed as actively exploited. It is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog.